dpdk l3fwd实现ip acl规则下发

L3fwd在L2fwd的基础上增加网络层的根据IP地址进行路由查找的内容。

DPDK的典型应用l3fwd可以看出,在某个核上运行的程序从指定的队列上接收,往指定的队列上发送,可以达到很高的cache命中率,效率也就会高。

l2fwd例子中,代码中网卡没有配置多队列,所以性能上有些局限性。

而l3fwd的例子中,网卡配置了多队列。

这就是在网络转发调试过程中,很多场景下直接使用l2fwd进行转发测试,往往达不到最佳效果的根本原因。

l2fwd中,报文转发流程相对简单,仅仅改了mac就发包了,无需过多判断。

l3fwd中,需查询路由表,相对实现复杂些。

dpdk的acl算法。大致用法如下:

配置如下格式的过滤规则,编译成规则树,并提供search的接口

 * '@'<src_ipv4_addr>'/'<masklen> <space> \

 * <dst_ipv4_addr>'/'<masklen> <space> \

 * <src_port_low> <space> ":" <src_port_high> <space> \

 * <dst_port_low> <space> ":" <dst_port_high> <space> \

 * <proto>'/'<mask>

规则文件定义例子:

@2.2.2.2/32 1.1.1.1/32 0 : 65535 0 : 65535 0/0

@2.2.2.3/32 1.1.1.1/32 0 : 65535 0 : 65535 0/0

@2.2.2.4/32 1.1.1.1/32 0 : 65535 0 : 65535 0/0

@2.2.2.5/32 1.1.1.1/32 0 : 65535 0 : 65535 0/0

@2.2.2.6/32 1.1.1.1/32 0 : 65535 0 : 65535 0/0

@2.2.2.7/32 1.1.1.1/32 0 : 65535 0 : 65535 0/0

/* main processing loop */
static int
main_loop(__rte_unused void *dummy)
{
    struct rte_mbuf *pkts_burst[MAX_PKT_BURST];
    unsigned lcore_id;
    uint64_t prev_tsc, diff_tsc, cur_tsc;
    int i, nb_rx;
    uint16_t portid;
    uint8_t queueid;
    struct lcore_conf *qconf;
    int socketid;
    const uint64_t drain_tsc = (rte_get_tsc_hz() + US_PER_S - 1)
            / US_PER_S * BURST_TX_DRAIN_US;
    prev_tsc = 0;
    lcore_id = rte_lcore_id();
    qconf = &lcore_conf[lcore_id];
    socketid = rte_lcore_to_socket_id(lcore_id);
    if (qconf->n_rx_queue == 0) {
        RTE_LOG(INFO, L3FWD, "lcore %u has nothing to do\n", lcore_id);
        return 0;
    }
    RTE_LOG(INFO, L3FWD, "entering main loop on lcore %u\n", lcore_id);
    for (i = 0; i < qconf->n_rx_queue; i++) {
        portid = qconf->rx_queue_list[i].port_id;
        queueid = qconf->rx_queue_list[i].queue_id;
        RTE_LOG(INFO, L3FWD,
            " -- lcoreid=%u portid=%u rxqueueid=%hhu\n",
            lcore_id, portid, queueid);
    }
    while (1) {
        cur_tsc = rte_rdtsc();
        /*
         * TX burst queue drain
         */
        diff_tsc = cur_tsc - prev_tsc;
        if (unlikely(diff_tsc > drain_tsc)) {
            for (i = 0; i < qconf->n_tx_port; ++i) {
                portid = qconf->tx_port_id[i];
                rte_eth_tx_buffer_flush(portid,
                        qconf->tx_queue_id[portid],
                        qconf->tx_buffer[portid]);
            }
            prev_tsc = cur_tsc;
        }
        /*
         * Read packet from RX queues
         */
        for (i = 0; i < qconf->n_rx_queue; ++i) {
            portid = qconf->rx_queue_list[i].port_id;
            queueid = qconf->rx_queue_list[i].queue_id;
            nb_rx = rte_eth_rx_burst(portid, queueid,
                pkts_burst, MAX_PKT_BURST);
            if (nb_rx > 0) {
                struct acl_search_t acl_search;
                prepare_acl_parameter(pkts_burst, &acl_search,
                    nb_rx);
                if (acl_search.num_ipv4) {
                    rte_acl_classify(
                        acl_config.acx_ipv4[socketid],
                        acl_search.data_ipv4,
                        acl_search.res_ipv4,
                        acl_search.num_ipv4,
                        DEFAULT_MAX_CATEGORIES);
                    send_packets(acl_search.m_ipv4,
                        acl_search.res_ipv4,
                        acl_search.num_ipv4);
                }
                if (acl_search.num_ipv6) {
                    rte_acl_classify(
                        acl_config.acx_ipv6[socketid],
                        acl_search.data_ipv6,
                        acl_search.res_ipv6,
                        acl_search.num_ipv6,
                        DEFAULT_MAX_CATEGORIES);
                    send_packets(acl_search.m_ipv6,
                        acl_search.res_ipv6,
                        acl_search.num_ipv6);
                }
            }
        }
    }
}

int
main(int argc, char **argv)
{
    struct lcore_conf *qconf;
    struct rte_eth_dev_info dev_info;
    struct rte_eth_txconf *txconf;
    int ret;
    unsigned nb_ports;
    uint16_t queueid;
    unsigned lcore_id;
    uint32_t n_tx_queue, nb_lcores;
    uint16_t portid;
    uint8_t nb_rx_queue, queue, socketid;
    /* init EAL */
    ret = rte_eal_init(argc, argv);
    if (ret < 0)
        rte_exit(EXIT_FAILURE, "Invalid EAL parameters\n");
    argc -= ret;
    argv += ret;
    set_default_dest_mac();
    /* parse application arguments (after the EAL ones) */
    ret = parse_args(argc, argv);
    if (ret < 0)
        rte_exit(EXIT_FAILURE, "Invalid L3FWD parameters\n");
    if (check_lcore_params() < 0)
        rte_exit(EXIT_FAILURE, "check_lcore_params failed\n");
    ret = init_lcore_rx_queues();
    if (ret < 0)
        rte_exit(EXIT_FAILURE, "init_lcore_rx_queues failed\n");
    nb_ports = rte_eth_dev_count_avail();
    if (check_port_config() < 0)
        rte_exit(EXIT_FAILURE, "check_port_config failed\n");
    /* Add ACL rules and route entries, build trie */
    if (app_acl_init() < 0)
        rte_exit(EXIT_FAILURE, "app_acl_init failed\n");
    nb_lcores = rte_lcore_count();
    /* initialize all ports */
    RTE_ETH_FOREACH_DEV(portid) {
        struct rte_eth_conf local_port_conf = port_conf;
        /* skip ports that are not enabled */
        if ((enabled_port_mask & (1 << portid)) == 0) {
            printf("\nSkipping disabled port %d\n", portid);
            continue;
        }
        /* init port */
        printf("Initializing port %d ... ", portid);
        fflush(stdout);
        nb_rx_queue = get_port_n_rx_queues(portid);
        n_tx_queue = nb_lcores;
        if (n_tx_queue > MAX_TX_QUEUE_PER_PORT)
            n_tx_queue = MAX_TX_QUEUE_PER_PORT;
        printf("Creating queues: nb_rxq=%d nb_txq=%u... ",
            nb_rx_queue, (unsigned)n_tx_queue);
        ret = rte_eth_dev_info_get(portid, &dev_info);
        if (ret != 0)
            rte_exit(EXIT_FAILURE,
                "Error during getting device (port %u) info: %s\n",
                portid, strerror(-ret));
        ret = config_port_max_pkt_len(&local_port_conf, &dev_info);
        if (ret != 0)
            rte_exit(EXIT_FAILURE,
                "Invalid max packet length: %u (port %u)\n",
                max_pkt_len, portid);
        if (dev_info.tx_offload_capa & RTE_ETH_TX_OFFLOAD_MBUF_FAST_FREE)
            local_port_conf.txmode.offloads |=
                RTE_ETH_TX_OFFLOAD_MBUF_FAST_FREE;
        local_port_conf.rx_adv_conf.rss_conf.rss_hf &=
            dev_info.flow_type_rss_offloads;
        if (local_port_conf.rx_adv_conf.rss_conf.rss_hf !=
                port_conf.rx_adv_conf.rss_conf.rss_hf) {
            printf("Port %u modified RSS hash function based on hardware support,"
                "requested:%#"PRIx64" configured:%#"PRIx64"\n",
                portid,
                port_conf.rx_adv_conf.rss_conf.rss_hf,
                local_port_conf.rx_adv_conf.rss_conf.rss_hf);
        }
        ret = rte_eth_dev_configure(portid, nb_rx_queue,
                    (uint16_t)n_tx_queue, &local_port_conf);
        if (ret < 0)
            rte_exit(EXIT_FAILURE,
                "Cannot configure device: err=%d, port=%d\n",
                ret, portid);
        ret = rte_eth_dev_adjust_nb_rx_tx_desc(portid, &nb_rxd,
                               &nb_txd);
        if (ret < 0)
            rte_exit(EXIT_FAILURE,
                "rte_eth_dev_adjust_nb_rx_tx_desc: err=%d, port=%d\n",
                ret, portid);
        ret = rte_eth_macaddr_get(portid, &port_l2hdr[portid].src_addr);
        if (ret < 0)
            rte_exit(EXIT_FAILURE,
                "rte_eth_macaddr_get: err=%d, port=%d\n",
                ret, portid);
        print_ethaddr("Dst MAC:", &port_l2hdr[portid].dst_addr);
        print_ethaddr(", Src MAC:", &port_l2hdr[portid].src_addr);
        printf(", ");
        /* init memory */
        ret = init_mem(NB_MBUF);
        if (ret < 0)
            rte_exit(EXIT_FAILURE, "init_mem failed\n");
        for (lcore_id = 0; lcore_id < RTE_MAX_LCORE; lcore_id++) {
            if (rte_lcore_is_enabled(lcore_id) == 0)
                continue;
            /* Initialize TX buffers */
            qconf = &lcore_conf[lcore_id];
            qconf->tx_buffer[portid] = rte_zmalloc_socket("tx_buffer",
                    RTE_ETH_TX_BUFFER_SIZE(MAX_PKT_BURST), 0,
                    rte_eth_dev_socket_id(portid));
            if (qconf->tx_buffer[portid] == NULL)
                rte_exit(EXIT_FAILURE, "Can't allocate tx buffer for port %u\n",
                        (unsigned) portid);
            rte_eth_tx_buffer_init(qconf->tx_buffer[portid], MAX_PKT_BURST);
        }
        /* init one TX queue per couple (lcore,port) */
        queueid = 0;
        for (lcore_id = 0; lcore_id < RTE_MAX_LCORE; lcore_id++) {
            if (rte_lcore_is_enabled(lcore_id) == 0)
                continue;
            if (numa_on)
                socketid = (uint8_t)
                    rte_lcore_to_socket_id(lcore_id);
            else
                socketid = 0;
            printf("txq=%u,%d,%d ", lcore_id, queueid, socketid);
            fflush(stdout);
            ret = rte_eth_dev_info_get(portid, &dev_info);
            if (ret != 0)
                rte_exit(EXIT_FAILURE,
                    "Error during getting device (port %u) info: %s\n",
                    portid, strerror(-ret));
            txconf = &dev_info.default_txconf;
            txconf->offloads = local_port_conf.txmode.offloads;
            ret = rte_eth_tx_queue_setup(portid, queueid, nb_txd,
                             socketid, txconf);
            if (ret < 0)
                rte_exit(EXIT_FAILURE,
                    "rte_eth_tx_queue_setup: err=%d, "
                    "port=%d\n", ret, portid);
            qconf = &lcore_conf[lcore_id];
            qconf->tx_queue_id[portid] = queueid;
            queueid++;
            qconf->tx_port_id[qconf->n_tx_port] = portid;
            qconf->n_tx_port++;
        }
        printf("\n");
    }
    for (lcore_id = 0; lcore_id < RTE_MAX_LCORE; lcore_id++) {
        if (rte_lcore_is_enabled(lcore_id) == 0)
            continue;
        qconf = &lcore_conf[lcore_id];
        printf("\nInitializing rx queues on lcore %u ... ", lcore_id);
        fflush(stdout);
        /* init RX queues */
        for (queue = 0; queue < qconf->n_rx_queue; ++queue) {
            struct rte_eth_rxconf rxq_conf;
            portid = qconf->rx_queue_list[queue].port_id;
            queueid = qconf->rx_queue_list[queue].queue_id;
            if (numa_on)
                socketid = (uint8_t)
                    rte_lcore_to_socket_id(lcore_id);
            else
                socketid = 0;
            printf("rxq=%d,%d,%d ", portid, queueid, socketid);
            fflush(stdout);
            ret = rte_eth_dev_info_get(portid, &dev_info);
            if (ret != 0)
                rte_exit(EXIT_FAILURE,
                    "Error during getting device (port %u) info: %s\n",
                    portid, strerror(-ret));
            rxq_conf = dev_info.default_rxconf;
            rxq_conf.offloads = port_conf.rxmode.offloads;
            ret = rte_eth_rx_queue_setup(portid, queueid, nb_rxd,
                    socketid, &rxq_conf,
                    pktmbuf_pool[socketid]);
            if (ret < 0)
                rte_exit(EXIT_FAILURE,
                    "rte_eth_rx_queue_setup: err=%d,"
                    "port=%d\n", ret, portid);
        }
    }
    printf("\n");
    /* start ports */
    RTE_ETH_FOREACH_DEV(portid) {
        if ((enabled_port_mask & (1 << portid)) == 0)
            continue;
        /* Start device */
        ret = rte_eth_dev_start(portid);
        if (ret < 0)
            rte_exit(EXIT_FAILURE,
                "rte_eth_dev_start: err=%d, port=%d\n",
                ret, portid);
        /*
         * If enabled, put device in promiscuous mode.
         * This allows IO forwarding mode to forward packets
         * to itself through 2 cross-connected  ports of the
         * target machine.
         */
        if (promiscuous_on) {
            ret = rte_eth_promiscuous_enable(portid);
            if (ret != 0)
                rte_exit(EXIT_FAILURE,
                    "rte_eth_promiscuous_enable: err=%s, port=%u\n",
                    rte_strerror(-ret), portid);
        }
    }
    check_all_ports_link_status(enabled_port_mask);
    /* launch per-lcore init on every lcore */
    rte_eal_mp_remote_launch(main_loop, NULL, CALL_MAIN);
    RTE_LCORE_FOREACH_WORKER(lcore_id) {
        if (rte_eal_wait_lcore(lcore_id) < 0)
            return -1;
    }
    /* clean up the EAL */
    rte_eal_cleanup();
    return 0;
}



DPDK: lib/acl/rte_acl.h File Reference

  • 1
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 9
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 9
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值